HNHacker News
TopNewBestAskShowJobs

devttyeu

721 karma · joined July 30, 2017

me at magik dot net
submissionscomments
devttyeu··on Ollaya – Ollama for open-source, Jev-style decision models
Yeah, speed is the one, I believe the default TypeSafe API quota is 1.5-2k queries per second (batched in bigger requests).

On the readme I'm so sorry to tell you that, but it's 100% written by Opus 5.5 with zero "pretty please don't write slop" prompting, it's just how slop is going to look like from now on. I've been writing code for 15 years or sth like that and the code is also what I'd call pretty reasonable..

devttyeu··on Ollaya – Ollama for open-source, Jev-style decision models
It is /possible/ to use an LLM.

But with Jev you're just paying for input (prefill) which is really fast, and in case of Jev specifically costs 50% of Deepseek V4.1 Flash (which has famously really cheap input token pricing).

I put 250MB / 1M lines of logs through Grev and it cost ~$10USD, DSv4.1 would be at least 10x that and much, much, much slower. With Jev/Grev that 1M requests took 10 mins

Edit: completely misread your question - yeah you could finetune specialized models to do that, probably based on some decent pretrained llm base, that is true for roughly any Jev-shaped problem. Do you want to bother doing that, also having to deal with having to host a zoo of specialized models?

devttyeu··on Ollaya – Ollama for open-source, Jev-style decision models
I have a lot of semi-practical examples of how you can use this model wrapped in unix-ish tools - https://github.com/aurorainfra/grev (readme links to docs of each tool with some more or less practical examples)

Really I think "smart grep" is a pretty good one ('look for an error looking vaguely like this'). Also I think sql-based shell history + decision model is quite good to make the last 'which one of those choices is best fit given users past few commands' etc.

devttyeu··on Show HN: Grev - Thinking Coreutils with Jev
Thought it would be funny to build, but those have actually helped me with log-combing already
devttyeu··on Oracle’s 6am layoff emails hit staff amid new wave of cuts
What else does Oracle have? Mostly just a bunch of IP that a sufficiently strong AI will be able to recreate for a fraction of each customers bill. Oracle is very aware.

Where is the value coming from when all knowledge work (and later manual work) is 10-100-10000x cheaper done by AIs? You probably don’t want to build models, too easy to move to another provider when one is better, open models eat your lunch etc. But there are still means of production to be owned but it’s just GPUs

devttyeu··on Ask HN: What are you working on? (September 2026)
Yeah I’m still iterating on the pitch and target audience, thanks for flagging.

It’s not a general coding tool, shortest description would be “personal/company data/process management layer” or “everything a company may want an on-prem datacenter and admin (dev)team for, accelerated by AI”.

Came from finding bug shortcomings in OpenClaw/Hermes where it’s not really close to having everything needed to organise and deal with big data in a safe or efficient way.

Basically the bottleneck is building a massive amount of software around agents which won’t happen in an all-in-one harness, this attacks that problem

devttyeu··on Ask HN: What are you working on? (September 2026)
Multi-org/Multi-team Software factory x Agent Sandbox with bring-your-own-harness model: https://xbin.dev

Built for myself and my companies, OSS, maybe looking for a founder if anyone wants to make it be something, I got enough things to run heh.

devttyeu··on IPFS Maintainers Winding Down
I run a company currently serving ~1.7B requests per day (~20k/s) to ipfs gateways, so presumably still some. Very likely a big chunk of that is bots scraping stuff.
devttyeu··on IPFS Maintainers Winding Down
Iroh got started with IPFS-style content-addressed blob transfers as the primary way to use it, still has that functionality but its now a bit of a second tier citizen. See https://docs.iroh.computer/protocols/blobs

Besides just p2p streams seem to be much more useful, those are plug-and-play into most software, e.g. I wrote https://github.com/magik6k/git-remote-iroh that just plugs the git remote proto into iroh and lets you move repo commits between computers by just copying a string from one place to another on push. Doing that with blobs - not gonna happen, not that easily.

devttyeu··on IPFS Maintainers Winding Down
"The next big thing" usually
devttyeu··on IPFS Maintainers Winding Down
Sad to see it go having been a maintainer some years ago.

For anyone wondering, there are more sustainable (with a viable, focused business backing the project) options to do p2p, namely Iroh - https://www.iroh.computer/ which was built by ex-IPFS ex-Protocol Labs devs (I have no relation to the team beyond having worked with them back in the day).

Sadly Protocol Labs is doing.. ehh whatever now, except apparently supporting the projects it got its VC/crypto funding from.

devttyeu··on LLM City – 3D render of all Kimi K3's weights as 2.5mm tiles
Not real weights, of course, but real model layout.
devttyeu··on Spaghettifying DRAM
Zen has completely different memory controller IP (UMC), that's configured at boot by AGESA/PSP. I doubt this exploit applies to modern Zen CPUs, however AMD are the only ones who could really confirm this.
devttyeu··on Spaghettifying DRAM
Ok, on 2. and in general this exploit only works on pre-Zen AMD platforms as the repo states in not-so-clear terms.

Zen changed DTC (DRAM Controller) to UMC (Unified Memory Controller), UMC is programmed at boot, and one would hope they figured that locking access to it makes sense when they were adding confidential compute support; Not clear though because there is no public documentation on it, so best we can hope for is some statement from AMD/3rd party researcher saying "this won't work on Zen because X/Y/Z"

devttyeu··on Spaghettifying DRAM
Yeah, just started looking at this with my team (we run a cloud with VM instance offering on AMD so this very much caught our eye)

So far seems this is about right:

1. You need platform register access, so seems can't KVM-escape with just this

2. Big question is what about breaking Confidential SEV-SNP guests from the host?

devttyeu··on Spaghettifying DRAM
Well, K3 has no problem, Sol is also fine-ish
devttyeu··on Spaghettifying DRAM
The big question is whether this can break out of KVM and whether it can be microrode patched / patched in any other way.

And whether it's really real in the first place.

devttyeu··on Docker Sandboxes – Disposable, isolated sandboxes for AI agents
For persistent-ish one-off apps https://xbin.dev/ (my project)

Has egress and ingress filtering, egress can be bound to host/internet/subnet or even better to internal apps (which are each separate netns) meaning you can do your own firewall/vpn/whatever per sandbox. Plus you control what other components in the sandbox env the app can communicate with.

Really not built for day-to-day dev work though, more like automating your company/life / getting rid of SaaS (e.g. for technical Founders / Sales etc, not exactly useful for dev work)

devttyeu··on Docker Sandboxes – Disposable, isolated sandboxes for AI agents
I did try to use those for some stuff: * Login requirement is something else * It's closed source last I checked * Pretty slow/unstable

There are many better namespace/container based options, VMs may be moderately more secure but when you more or less trust your agent and code you can do with lesser containment. And with the recent CVEs in kvm honestly there isn't a huge deal of difference vs namespaces.

(I'm building https://xbin.dev/ for some time now for managing my personal code/apps, a project which started specifically after Docker Sandboxes broke on me some time ago)

devttyeu··on LG monitors silently install software through Windows Update without consent
This is so much worse that the title makes it out to be:

  1. Your OS installs malware (technically manufacturers software) from a 3rd party vendor in background, zero user interaction
  2. Happens as soon as you or anyone with physical access plug in a device into the HDMI port
  3. That malware has internet and full system access, no sandboxing
  4. It starts with every system boot
  5. This software gets installed when you plug in a new LG monitor
  6. OR ALREADY HAD AN OLDER LG MONITOR PLUGGED IN, BECAUSE LG APPARENTLY ROLLED THIS OUT FOR MANY OLDER MODELS TOO!!
  7. And yes, if you think that's horrendous, as mentioned in the video below, that also applies to 'Professional' LG monitors!

This situation has.. no precedent as far as I can tell..

GamersNexus has a video diving deeper into what LG did here - https://www.youtube.com/watch?v=Q9uefFYe6bM

devttyeu··on Kimi K3, and what we can still learn from the pelican benchmark
> How does the prompt “Generate an SVG of a pelican riding a bicycle” add up to 95 input tokens? OpenAI’s tokenizer counts 10, Anthropic’s counts 10 for Opus 4.6, 30 for Opus 4.7 and 25 for Sonnet 5/Fable 5. Prompting “hi” to Kimi K3 counted 86 tokens, suggesting there may be an 85 token hidden system prompt. It refused to leak it though.

This is quite possibly reasoning-effort prompt which is injected before the opening <think> token whenever you set a custom reasoning effort, see e.g. DeepSeek-V4 max mode prompt: https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro/blob/main...

devttyeu··on Show HN: Firefox in WebAssembly
Oh wow didn't expect this to be either possible or this perform so well.

Also fascinating how small the wasm binary is. I made a Wasm port of FreeCad (also had a fairly popular thread here a few days ago) but that image was close to 300MB uncompressed / 90MB compressed with Brotli.

(btw none of my wasm CAD ports seem to run, each with slightly different flavors of missing wasm features it seems - I have them linked on https://magik.net if you want to debug for whatever reason)

devttyeu··on Ask HN: What Are You Working On? (July 2026)
Thought of using Iroh/LibP2P under the hood?
devttyeu··on Ask HN: What Are You Working On? (July 2026)
Building a rootless, namespace powered (deeply stretching the definition of a container), on demand application workspace.

- Each component in a mini app in a heavily locked down container - Components are deployed and built in a web workspace, in the same workspace you can open a terminal and use your favourite coding agent to work on component code (each terminal is itself heavily sandboxes, has rw access only to the edited component code and users home dir) - Everything comes with heavy rbac and minimum permissions - Oh so much more

Explaining this well is hard, much like explaining to someone what Kubernetes or AWS does. This is at a level of what a sophisticated company infrastructure team would run, just as a workspace you can deploy for yourself easily and agents just build within that framework (I’m a cofounder of a infra/compute/datacenter startup and intimately familiar with this kind of complexity)

The main thesis is that Claw-style agents still feel like school projects, and that in the agentic era apps on demand will be more of a thing, and that the current systems weren’t built to deal with a whole new app built every few minutes.

May or may not end up as open source soon

devttyeu··on An iroh powered smart fan
Any plans to standardize Iroh IoT protocols, e.g. Matter over Iroh / Some other standard that would be plug-able to things like Home Assistant?
devttyeu··on FreeCAD in the Browser
(I made this port) Fwiw I personally had no reason to do this port beyond using it as a benchmark of the agentic capability of Fable, where something of this shape is IMO a way better gauge than those dumb X.com 'I oneshot game with models X/Y/Z this is how it compares'

I published the actual prompts, and you can see quite clearly that vs Opus which is ok at implementing one big feature, Fable was really able to push through a good chunk of the port. That said it definitely didn't one-shot the port, it also didn't figure out a broken docker sbx sandbox by itself, and also later needed some gaslighting into thinking that the port is not really that hard (by any human measure it was quite hard given the scope of code involved.. The nearly 200MB wasm binary is mostly code afaict..). So there are some clear patterns of how the model was trained and also roughly the scope of task visible in those traces. What I see is that it likes prompts that would take an L4/L5 2-4 weeks to do with Cursor ~2 years ago, more needs some direction and deliberate prompting.

devttyeu··on FreeCAD in the Browser
I will also note that it's possible to compile this with wasm asyncify, but the result iirc is a ~400MiB Wasm binary that will crash the browser tab before you will be able to do anything useful in it.
devttyeu··on FreeCAD in the Browser
I made the port, roughly ~one maxed out Claude Max 20x sub, at the bottom of the article I've shared the full claude code transcripts, so you can probably to some rough math on token usage with that.

Edit: to be precise 'maxed out' means one weekly limit on fable used over those 4 days

devttyeu··on FreeCAD in the Browser
Author of the port here, you need a browser with JSPI support, which means recent Chrome, or Firefox Nightly with the feature flag flipped, or Firefox from the future.
devttyeu··on LibreCAD in the Browser
Are you sure you created a new canvas first? Should be black, not grayish.
Page 1 of 4Next →